Business Continuity Vendor Manager

Kitsap Credit UnionBremerton, WA
$91,537 - $110,285Hybrid

About The Position

The Business Continuity & Vendor Risk Manager is responsible for the leadership, administration, and continuous improvement of Kitsap Credit Union's Business Continuity Management and Third-Party/Vendor Risk Management programs. Serving as the primary subject matter expert for operational resilience and third-party risk, this position ensures critical business functions, external service provider relationships, and third-party engagements are identified, assessed, monitored, tested, and governed in alignment with regulatory expectations, internal policies, and KCU's risk appetite. As an individual contributor, the role provides enterprise-wide leadership through program ownership, governance, risk oversight, reporting, and cross-functional collaboration. The position partners closely with business owners, Information Security, Information Technology, Compliance, Internal Audit, and executive leadership to strengthen organizational resilience, enhance third-party risk management practices, reduce operational risk exposure, and support audit and examination readiness.

Requirements

  • Advanced knowledge of business continuity, operational resilience, vendor management, third-party risk, and risk governance concepts within a regulated financial institution environment.
  • Ability to independently manage complex risk programs, balance strategic and operational priorities, and drive cross-functional execution without direct supervisory authority.
  • Strong analytical, critical thinking, documentation, and problem-solving skills, with the ability to assess risk, identify gaps, and recommend practical remediation actions.
  • Strong written and verbal communication skills, including the ability to prepare executive-level summaries, governance reporting, issue documentation, and business-owner guidance.
  • Ability to interpret regulatory expectations and translate them into sustainable program practices, documentation standards, and monitoring routines.
  • High degree of judgment, discretion, accountability, and attention to detail when handling sensitive vendor, continuity, risk, audit, and examination information.
  • Proficiency with Microsoft Office Suite and ability to work with vendor management, GRC, reporting, document management, or workflow tools.
  • Demonstrates a high level of engagement and active collaboration, contributing to a positive team environment and modeling KCU’s core values.
  • 5 plus years in risk management.
  • Experience with NCUA, FFIEC, GLBA, privacy, cybersecurity, operational resilience, disaster recovery, or third-party risk regulatory expectations.
  • Experience managing or improving a vendor management, TPRM, business continuity, operational resilience, or GRC program.
  • Professional certification such as CBCP, MBCP, CRVPM, CTPRP, CTPRA, CRISC, CERP, PMP, or similar risk, continuity, vendor management, or governance credential.

Nice To Haves

  • Credit union or community financial institution experience preferred.
  • Experience owning full cycle of vendor management program.

Responsibilities

  • Own and manage the credit union’s Business Continuity Management (BCM) program framework, including business impact analysis, continuity planning, recovery strategy documentation, plan maintenance, testing, exercises, and issue tracking.
  • Organization wide leadership of departmental continuity plans are current, actionable, and aligned to critical business processes, recovery objectives, dependencies, and member-impact considerations.
  • Lead enterprise-level tabletop exercises, scenario testing, and post-exercise reviews; document results, lessons learned, and remediation activities through closure.
  • Partnering cross functionally identifying critical operations, internal and external dependencies, recovery gaps, and opportunities to strengthen continuity capabilities across the organization.
  • Collaborate with IT, Information Security, Operations, Facilities, and other stakeholders on disaster recovery dependencies, incident response coordination, and continuity-related communications.
  • Own and manage the third-party risk management (TPRM)/vendor risk program lifecycle, including vendor onboarding, inherent risk assessments, due diligence, risk tiering, ongoing monitoring, contract review, issue escalation, and periodic reassessments.
  • Provide risk-based oversight of critical and high-risk vendors, including review of financial, operational, information security, business continuity, compliance, privacy, and service performance considerations.
  • Partner with business owners to clarify vendor ownership, monitoring expectations, documentation requirements, risk acceptance needs, and accountability for identified gaps or remediation plans.
  • Monitor vendor performance, control issues, incidents, emerging risks, and relationship changes that may affect KCU’s risk exposure or continuity posture.
  • Coordinate with Compliance, Information Security, Finance, and business stakeholders to support contract risk review and ensure key risk considerations are addressed before or during vendor engagement.
  • Develop and maintain program documentation, standards, procedures, templates, calendars, dashboards, and evidence repositories to support consistent execution and examiner-ready documentation.
  • Prepare periodic reporting for the VP of Risk Management, Enterprise Risk Management Committee, executive leadership, and other governance forums regarding BCM and TPRM status, key risks, testing results, issues, exceptions, and remediation progress.
  • Maintain awareness of applicable NCUA, FFIEC, and related regulatory guidance impacting business continuity, operational resilience, third-party risk management, and external service provider oversight.
  • Key role in internal audits, external audits, regulatory examinations, and management requests by providing documentation, analysis, responses, and corrective action tracking related to BCM and TPRM.
  • Escalate material vendor, continuity, operational resilience, or compliance concerns to the VP of Risk Management and appropriate governance channels in a timely and well-documented manner.
  • Evaluate program maturity and recommend enhancements to strengthen efficiency, consistency, reporting, risk visibility, ownership, and alignment with KCU’s enterprise risk management framework.
  • Identify opportunities to reduce reliance on outsourced support by building internal expertise, standardizing workflows, improving tools/templates, and clarifying first-line business owner responsibilities.
  • Provide training, guidance, and consultative support to business units on continuity planning, vendor risk expectations, risk assessments, documentation requirements, and issue remediation.
  • Support broader ERM initiatives as needed, including risk assessments, key risk indicators, risk appetite monitoring, policy governance, project risk review, and operational risk reporting.

Benefits

  • Bonus Target: 9%
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service